Description
Railo is an open-source alternative to the popular Coldfusion application server, implementing a FOSSy CFML engine and application server. Multiple critical vulnerabilities were reported in this application server. This test has confirmed a cross-site scripting vulnerability in the administration panel.
Remediation
Upgrade to the latest version of Railo.
References
Related Vulnerabilities
WordPress Plugin Events Calendar 'ec_management.class.php' Cross-Site Scripting (6.7.11)
WordPress Plugin WP Custom Fields Search Cross-Site Scripting (1.2.34)
WordPress Plugin Zephyr Project Manager Cross-Site Scripting (3.2.40)
WordPress Plugin Widget Shortcode Cross-Site Scripting (0.3.5)
WordPress Plugin Request Quote via Whatsapp for Woocommerce Cross-Site Scripting (1.0.1)